CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91373  CVE-2016-4554  Candidate  mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.  Assigned (20160506)  None (candidate not yet proposed)    View
26093  CVE-2007-2736  Candidate  PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.  Assigned (20070517)  None (candidate not yet proposed)    View
91629  CVE-2016-4810  Candidate  Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View
26349  CVE-2007-2992  Candidate  Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields.  Assigned (20070604)  None (candidate not yet proposed)    View
91885  CVE-2016-5066  Candidate  Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.  Assigned (20160526)  None (candidate not yet proposed)    View

Page 19460 of 20943, showing 5 records out of 104715 total, starting on record 97296, ending on 97300

Actions